What this is about
Every event that a CIAS module reports goes into the audit. The events are arranged in five groups, one per module, two for cias-user. In the audit an entry is named by group and kind, such as UserEvent.Suspended.
The five groups
When: cias-registration, in the course of a registration
Initiated (request accepted, email sent; with flow), Verified (link clicked), Completed (provisioned; with Keycloak ID and tenant), Rejected (rejected; with reason), Failed (provisioning failed; with reason), Expired (cleaned up; with last state and whether the account was deleted).
Result: See The states of a registration
When: cias-user, in user management
Recorded (user record created; with Keycloak ID and home tenant), Activated (enabled or reactivated), Suspended (suspended; with reason), Closed (closed; with reason), Moved (moved to another home tenant; from, to), PasswordSetupLinkSent (password link sent; with address, without the link).
Result: See The lifecycle of a user
When: cias-user, around the consent for a user switch
Requested (consent requested; who, whom, mode, end, reason), Granted (consent given, directly or by approving a request), Declined (request declined), Revoked (consent revoked or request withdrawn; with who revoked it), FirstUsed (consent used for the first time). Each with consent ID, both persons and tenant.
Result: See User switch by header
When: cias-tenancy, in the lifecycle of a tenant
Created (created), Activated (in service, also after provisioning), Suspended (suspended), Resumed (resumed), Closed (closed), ProvisioningFailed (setup failed; with reason). Each with ID and key of the tenant.
Result: See The lifecycle of a tenant
When: cias-authorization, for role grants
Granted (granted; with end date and grantedBy), Revoked (revoked; with revokedBy and reason), Expired (end date reached), Activated (start of a scheduled grant reached), WindowChanged (window changed when the same role was granted again). Each with grant ID, person, client, role and tenant.
Result: See Grant a role and Time-limited roles
All events in one table
| Entry in the audit | Occasion | Records |
|---|---|---|
RegistrationEvent.Initiated | registration accepted | ID, flow |
RegistrationEvent.Verified | address confirmed | ID |
RegistrationEvent.Completed | registration finished | ID, Keycloak ID, tenant |
RegistrationEvent.Rejected | rejected | ID, reason |
RegistrationEvent.Failed | provisioning failed | ID, reason |
RegistrationEvent.Expired | expired registration cleaned up | ID, state, account removed yes/no |
UserEvent.Recorded | user record created | user ID, Keycloak ID, home tenant |
UserEvent.Activated | user active | user ID |
UserEvent.Suspended | user suspended | user ID, reason |
UserEvent.Closed | user closed | user ID, reason |
UserEvent.Moved | home tenant changed | user ID, old and new tenant |
UserEvent.PasswordSetupLinkSent | password link sent | user ID, address |
SwitchConsentEvent.Requested | consent for a user switch requested | consent ID, requesting person, target person, tenant, mode, end, reason |
SwitchConsentEvent.Granted | consent given | consent ID, both persons, tenant, mode, end, whether on request, reason |
SwitchConsentEvent.Declined | request declined | consent ID, both persons, tenant |
SwitchConsentEvent.Revoked | consent revoked or request withdrawn | consent ID, both persons, tenant, who revoked |
SwitchConsentEvent.FirstUsed | consent used for the first time | consent ID, both persons, tenant, mode |
TenantEvent.Created | tenant created | tenant ID, key |
TenantEvent.Activated | tenant in service | tenant ID, key |
TenantEvent.Suspended | tenant suspended | tenant ID, key |
TenantEvent.Resumed | tenant resumed | tenant ID, key |
TenantEvent.Closed | tenant closed | tenant ID, key |
TenantEvent.ProvisioningFailed | setup failed | tenant ID, key, reason |
AuthorizationEvent.Granted | role granted | grant, person, role, tenant, end date, grantedBy |
AuthorizationEvent.Revoked | role revoked | grant, person, role, tenant, revokedBy, reason |
AuthorizationEvent.Expired | time-limited role expired | grant, person, role, tenant |
AuthorizationEvent.Activated | scheduled role begins | grant, person, role, tenant |
AuthorizationEvent.WindowChanged | window of a running grant changed | grant, person, role, tenant, start, end, who, reason |
No event contains a link, a token or a password. PasswordSetupLinkSent names the address, not the link.
What reports no event
The audit only contains what a module reports as an event. These actions report none and are therefore not in the audit:
- creating, changing, deleting groups, adding and removing members
- creating, retiring or deleting roles in the catalog, and the reconciliation with Keycloak. What a reconciliation did is in its report
- writing attribute values, in the profile or per tenant
- changing a tenant’s validity period
- renaming a user or replacing their CIAS attributes. When existing accounts are imported, a
UserEvent.Recordedis created per account - saving and deleting mail templates. Who changed it last is in
updatedByon the template - tenant and user switches by header, that is every single switched request. Of the user switch, only the first use of a consent is in the audit, see above
- logging in, logging out, renewing the token. Keycloak keeps track of that